Skip to content

CVE-2026-1703 on CTRL-OS 26.05

Aliases: CVE-2026-1703

Packages: python3Packages.pip

Status: Plausible

Advisory Information

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Updates

2026-07-16 23:36 CEST

Metadata changes:

  • Status for package python3Packages.pip: “Plausible

(Amended on: 2026-07-16 23:37 CEST)

2026-06-04 00:04 CEST

Metadata changes:

  • Status for package python3Packages.pip: “New